PatchSiren

kerberosmansour CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH kerberosmansour CVE published 2026-08-31

CVE-2026-82862

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T09:17:06.643Z and has not been modified since then. CVE-2026-82862 is a vulnerability in Hulumi versions before v1.3.2 that allows workspace files to shadow the intended threat-model helper script, enabling attackers to execute arbitrary code during local skill execution by placing malicious file [truncated]

CRITICAL kerberosmansour CVE published 2026-08-31

CVE-2026-82859

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T09:17:06.210Z and has not been modified since then. This CVE affects hulumi versions before v1.3.2, allowing tag-on-create bypasses for hulumi:iac-role protections via a weakened SCP template. Users of hulumi versions before v1.3.2, security teams, and IAM administrators should review and remedia [truncated]

MEDIUM kerberosmansour CVE published 2026-07-24

CVE-2026-48037

CVE-2026-48037 is a security vulnerability in Hulumi, an open-source toolkit for secure-by-default cloud and platform infrastructure components. Prior to version 1.4.0, the AccountFoundation reuse paths could silently downgrade GuardDuty and Security Hub posture. This issue was patched in version 1.4.0. The vulnerability has a CVSS score of 6.3 and is considered medium severity. Users of Hulumi versions p [truncated]

HIGH kerberosmansour CVE published 2026-07-24

CVE-2026-48036

Hulumi is an open-source toolkit for cloud and platform infrastructure components. A security issue in versions prior to 1.4.0 could lead to transient adapter failures being silently cached as 'all clear' or ordinary provider-version churn being falsely promoted to incident severity. This issue may impact downstream incident workflows that rely on the verdict source. Users of Hulumi should be aware of thi [truncated]

HIGH kerberosmansour CVE published 2026-07-24

CVE-2026-48035

CVE-2026-48035 is a HIGH severity vulnerability in the Hulumi open-source toolkit. The vulnerability affects consumers using AccountFoundation, allowing any S3-delete-capable principal to delete CloudTrail / Config audit logs, despite the startup-hardened tier being believed to guarantee tamper-resistance. Sandbox-tier deployments had no audit immutability. This issue has been patched in version 1.4.0. Af [truncated]

HIGH kerberosmansour CVE published 2026-07-24

CVE-2026-48032

CVE-2026-48032 is a security issue in Hulumi, an open-source toolkit for secure-by-default cloud and platform infrastructure components for Pulumi. The issue allows for the bypass of IAM-role policy checks when a role trusts multiple OIDC providers. This CVE record was published on 2026-07-24T19:16:58.190Z and has not been modified since then. The vulnerability has been addressed in version 1.4.0 of Hulum [truncated]